It's KERI or Surveillance - Samuel Smith

July 2026 · 54:25

0:00 Hello, my name is Samuel Smith. I'm

0:03 with the KERI Foundation. I'm also

0:06 the originator of the KERI suite of

0:08 protocols which are gaining adoption in

0:12 various sectors. I wanted to have a

0:16 discussion today about what I'm calling

0:18 the last best hope for individual

0:21 control digital ID in an AI world. And

0:23 it was prompted by the recent release by

0:26 the Five Eyes surveillance

0:29 conglomerate between those

0:32 countries about the cyber

0:34 cyber security threat that

0:37 foundational genAI models pose and

0:41 contrasting that with what KERI

0:44 provides and KERI stands for Key Event

0:47 Receipt Infrastructure.

0:49 It's a technical term but basically

0:51 it's a digital identity system that

0:54 retains individual control over their

0:57 identity which has some important

0:59 properties. So I want to talk about that

1:01 in more detail.

1:03 this is an excerpt from the report,

1:08 the link is there, from the NSA. It's

1:11 saying that frontier AI models are

1:15 anticipated to exceed current industry

1:17 expectations.

1:19 This is a very technically-worded

1:25 warning basically

1:29 in months not years these AI

1:34 models will overwhelm

1:37 any cyber security

1:39 capabilities of existing systems and so

1:42 they're basically telling everyone in

1:45 this article (it's a short article) you

1:48 need to change your stance. You need

1:51 to, change how you do things

1:54 because we can't guarantee that your

1:57 current security systems will survive

2:00 what's happening. And what is

2:01 happening is that certain foundation

2:04 models, Mythos for example is one were

2:07 developed to try to provide better cyber

2:09 security, but in the process of training

2:11 them to be better at detecting

2:14 exploits, they also became good at

2:18 exploiting exploits. And so that

2:21 means that

2:22 other less,

2:25 shall we say,

2:28 virtuous parties are building comparable

2:31 models. And once those are

2:34 available to cyber attackers, then

2:37 pretty much the current way that we do

2:40 digital identity, which is what digital

2:42 security is based on, will be broken

2:46 everywhere. And that's a problem. And

2:50 so we need to start doing something

2:51 about it. What that means is, is that we

2:54 actually have two paths forward.

2:57 The two paths are 1: AI based

3:00 digital identity and 2: KERI based digital

3:02 identity. When I say KERI I mean the

3:04 KERI suite of protocols. There's a

3:05 bunch of protocols bunch of different

3:07 things that are associated with KERI.

3:09 When I say AI based digital identity,

3:11 I'm talking about what the Five

3:14 Eyes Report recommended is that people

3:16 start using AI-based counter

3:19 measures, defensive measures. In other

3:21 words, it's like a

3:24 <i>spy versus spy</i> sort of thing

3:28 where both sides have AIs and

3:31 the AIs are working really hard to

3:33 either defend against cyber attack or to

3:35 engage in cyber

3:38 attacks. And so they're saying

3:41 everybody needs to start using AI to

3:43 defend themselves because the AI

3:46 attackers will be able to defeat your

3:49 current identity security systems and

3:52 that's a potential

3:54 problem. Now KERI, as we'll talk

3:58 about a little bit, was designed to be

4:00 highly resilient in this sort of

4:03 scenario. So what does an AI-based

4:06 digital identity look like? Well, it's a

4:08 digital persona that is derived from

4:11 continuous tracking and statistic

4:12 correlation of one's behavior and

4:14 biometrics expression. Basically, the AI

4:18 creates

4:20 a digital picture of

4:24 your behavior based on tracking and

4:26 correlating your behavior and then an

4:28 attacker has to impersonate

4:31 something that correlates better to

4:34 your behavior than your own

4:36 behavior. And so as long as your AI is

4:38 doing better job of correlating your

4:40 behavior and collecting those

4:44 signals called fraud signals

4:47 or anti-fraud signals then the AI can

4:51 say no it's you, and not an

4:53 impersonator, whereas the attacker

4:55 is saying no I can create an AI that can

4:57 impersonate you, can deep fake you, can

4:59 can make it look like it's you, and

5:02 so what happens is that everything that

5:04 you're protecting digital identity AI

5:07 learns how to do to better identify you,

5:09 the attacker will

5:12 eventually learn how to

5:13 better impersonate you. And so it's just

5:16 a continuous cycle. And the only way

5:18 that you win is if your protection AI

5:23 has as much information as it possibly

5:25 can have about your behavior so that it

5:28 can do a better job of creating a

5:30 digital persona that matches you. So if

5:32 that isn't scary from a privacy tracking

5:35 surveillance perspective, you don't

5:37 know what scary is because that is

5:39 pretty scary.

5:40 But that's what that looks like.

5:44 Whereas KERI is based on a

5:47 cryptographically-derived fault-tolerant

5:50 survivable ID (red.) and it's survivable to AI

5:53 cyber attack. We call it perpetual ID.

5:56 It isn't based on the

5:59 weak things that current

6:02 internet-based identity are based on

6:04 which are largely shared secrets. It's

6:06 not based on the weaknesses that are in

6:09 the DNS certificate authority system and

6:12 TLS and OAuth and OIDC and all of these

6:15 systems that we have developed

6:17 over the last 30 years that are now

6:18 vulnerable to AI cyber attacks.

6:21 It's a ground up new design that

6:23 is designed from the beginning to be

6:27 fault tolerant to survive attack to

6:30 be able to detect compromise and recover

6:31 from it. So it is designed

6:35 to be resilient to these these sorts of

6:37 attacks.

6:39 So what happens is that if you go

6:42 with AI-based identity you can get

6:44 protection but inevitably it's going to

6:47 be totally centralized with zero

6:49 privacy. Whereas if you go the KERI

6:51 route, it's fully decentralized with

6:53 best possible privacy. And that doesn't

6:55 mean that you have the privacy that

6:58 maybe you thought you could have. It

6:59 means it has the best privacy you

7:01 possibly can have given we're living in

7:04 this new AI environment where AIs are

7:08 consuming all of the data on the

7:10 internet and there have available to

7:11 them, data to correlate pretty

7:14 much anything about anything you do.

7:16 So we can talk about it in more detail

7:18 about what best possible privacy looks

7:20 like. So what we want to do is in

7:24 this discussion is answer some high-level

7:26 questions about what this means.

7:29 So these questions have topics and then

7:32 there's a question and then I'm going to

7:33 go into more detail on that. But

7:36 let's go back and remember we're talking

7:39 about AI-based digital identity which

7:41 NSA and the major security organizations

7:45 from the Five Eyes countries have said (implicitly, red)

7:48 “everyone needs to start adopting” or the

7:51 alternative is a KERI based digital

7:52 identity. KERI's not as well

7:54 known, so people don't know about it.

7:56 Although it's got some significant

7:58 adoption vectors, including one is called

8:00 State Endorsed Digital Identity (SEDI).

8:02 The other one's called Open Verifiable

8:03 Calling (OVC), which is getting rid

8:06 of spam in calling, and in the

8:10 healthcare sector, there's

8:12 work on using KERI for

8:16 patient ID. All of those are major

8:20 significant adoption vectors that

8:24 that could put KERI in a position to

8:26 be the last best hope for individual

8:30 identity because if we go down the AI

8:32 route, we may get security. It's an arms

8:34 race. It'll always be an arms race.

8:38 But we won't have any

8:39 semblance of user control or privacy.

8:42 So, let's talk about that.

8:47 The Five Eyes statement calls for AI

8:50 assisted defense. So the question is how

8:53 do we ensure AI remains subordinate to

8:55 humans, law, policy, and cryptographically

8:57 verifiable identity infrastructure

8:59 rather than becoming a de facto

9:00 authority.

9:04 Well the way that we ensure that is that we

9:07 need to have cryptographically

9:09 verifiable identity in the first place.

9:10 If we don't have that, then we can never

9:13 ensure that it doesn't become a de facto

9:14 authority because we can't tell what

9:17 it's doing. It's not transparent. It's

9:19 not observable. It's basically an AI and

9:23 that AI is going to make decisions about

9:25 who you are. And the

9:28 goal is to protect you from fraud,

9:30 but AIs themselves don't have any

9:35 inherent structure that allows them to

9:38 separate out what is sensitive

9:40 information and sensitive authority,

9:42 and sensitive things that it

9:44 should do or not do versus anything that

9:47 it's within its feature space or

9:52 weight space, based on the

9:56 the prompts that it's received and the

9:58 objectives that it's received and the

10:00 temperature by which it's deciding which

10:03 path to follow

10:06 and I can go into more detail but OWASP

10:08 recently released in March a 100-page

10:12 cyber security report on the new AI

10:15 threat and it is stark and because

10:19 the AI threat poses a threat

10:22 that hasn't ever existed before and there

10:24 aren't any

10:26 solutions for it. They say that in

10:29 the report. All you can do is to try to

10:31 mitigate it to some degree.

10:34 So, how we ensure it? First is:

10:37 we have to have

10:38 cryptographic verifiable identity

10:40 infrastructure. So that that is the

10:44 authority and individually

10:46 controlled. So what are the hardest

10:49 legal technical governance mechanisms

10:52 that are needed to ensure

10:54 that every significant AI action

10:57 remains attributable or accountable to

10:59 humans and organizations? Well, that

11:01 means that we have to build a regulatory

11:04 and a legal

11:07 bullwork for our individual rights.

11:11 The original Constitution of the United

11:13 States has a a couple of

11:15 amendments and the fourth and fifth

11:16 amendments, but those were written in an

11:19 age when there wasn't a digital realm

11:21 when pretty much everything

11:25 was on paper. Information was

11:28 disseminated on paper. We now have a

11:30 digital realm where information is

11:34 disseminated electronically. And the way

11:37 you protect yourself in the digital

11:40 realm and the way you protect your

11:41 identity, your information, your

11:43 presence is different

11:46 enough that we can't rely solely on

11:49 those two protections. We need to have

11:51 additional protections for that. And one

11:54 of those protections is called a “duty of

11:56 data loyalty”. It's probably the

11:59 best legal framework that's been

12:01 developed over the last few years.

12:03 There's some legal scholars that have

12:05 been working on it, written several

12:07 papers on it and the state of

12:10 Utah recently adopted it in the

12:12 legislation.

12:14 That requires that people who

12:16 process data about you must use that

12:20 data in a way that is in your best

12:22 interest. And that's the

12:25 start. And then you have to layer on top

12:27 of that a mechanism for people to be

12:31 in control of their identity to be able

12:33 to then express their preferences. And

12:36 it's not simply consent. It's actual

12:40 engaging in what

12:45 is in their best interest and attaching

12:48 to the use of that data what is

12:51 called chain-link confidentiality where

12:53 the where the terms and the follow

12:57 the data as it goes through the system

12:58 so that you have an ability to

13:01 enforce it so that it also includes

13:03 citizen enforcement or citizen recourse.

13:06 So there's several there's layers of

13:08 mechanisms that we need to put into

13:10 place and we're starting to do that in

13:12 some places. The state of Utah is

13:14 being a leader in it and there's a there

13:16 is a coalition of other states that

13:19 are looking at creating legislation the

13:21 same way that it gives us an opportunity

13:23 to be able to do that. But absent

13:25 that it's going to be very

13:29 difficult to stem the tide of what's

13:32 happening with AI and because of

13:35 the urgency it makes it all the more

13:37 problematic.

13:42 So the NSA's reports calls for

13:46 stronger identity and access controls.

13:49 Right. Well there's a problem

13:52 there.

13:54 the problem is what counts

13:56 as stronger, right? I mean, the

14:00 current controls and people have been

14:03 using them for years and

14:06 the and people keep strengthening them

14:08 and they keep adding to them, but

14:10 the AI can attack them in such

14:14 a broad way now that they need

14:17 to be strengthened

14:20 in a way not ever done before.

14:22 It's like I guess you could say it's

14:24 like going from armor made

14:28 out of leather to armor made out

14:31 of steel, right? Like to go from

14:36 weak to strong, but you don't have the

14:38 ability to build steel armor yet. You

14:40 haven't invented steel. So, what do you

14:42 do?

14:44 So KERI was designed from the ground

14:47 up to not require an AI to defend

14:52 against an AI. It was designed to use

14:54 cryptography in the best possible way

14:57 that you can use cryptography

14:59 which requires key management

15:01 and it requires key management done in a

15:04 special way. And if you do key

15:05 management in that way,

15:07 then you can build a system

15:11 that is resilient to these sorts of attacks

15:13 because it doesn't have the

15:14 weaknesses which are built into the

15:16 current controls because of the

15:20 state of technology 30 years ago when

15:22 these systems were designed and then

15:24 they've been bolted on and added on and

15:26 modified but the core architecture

15:28 hasn't changed in 30 years whereas

15:30 KERI is a new architecture.

15:34 so this question

15:37 is which weaknesses in current

15:40 identity systems become most dangerous

15:41 when attackers can operate at AI speed

15:44 and scale. Well, most vulnerabilities

15:50 typically employ

15:54 a a combination of vulnerabilities. So

15:58 you might have an algorithmic

16:01 an infrastructure,

16:03 a software and an operating system

16:07 and a usage vulnerability that together

16:11 enable an attack. A recursive

16:14 privilege escalation attack often takes

16:17 advantages of multiple vulnerabilities

16:19 to be able to both move

16:21 vertically and horizontally in an

16:26 or in an access control organizational

16:29 space by exploiting different

16:32 different degrees of vulnerabilities.

16:34 And so it doesn't get to where it

16:36 wants to go all at once. It just

16:38 gradually works there because it finds

16:41 what's broken at each point and then

16:44 searches for the next exploit, right?

16:48 And with AI, they can search faster.

16:51 They can combine exploits faster

16:55 because they can search the whole space

16:56 and they go "Oh, wait..."

16:58 In fact, there was a recent paper, I think

17:00 last week, where they were able to

17:02 exploit the memory security model in

17:07 Apple's M5 architecture

17:10 through a combination of human and

17:13 machine AI analysis that the humans

17:18 could've never done on their own

17:20 because they just didn't have the

17:22 ability to analyze all of the possible

17:24 different things they could think about.

17:25 they didn't necessarily know how to

17:28 how to finish the exploit but with the

17:30 human guidance in combination

17:33 so AI speed and scale

17:36 is not just the AI itself it's fact the

17:38 attackers are human, the

17:41 most of these attacks are guided by

17:44 humans, either criminals or nation states,

17:47 that want to come after

17:49 critical or valuable infrastructure and

17:52 the AI just is a force multiplier for

17:55 for all of those types of attacks,

17:57 not júst, but is for sure a force

17:59 multiplier. And that means that

18:02 even hard to find unknown exploits

18:07 that are latent, that are in your system

18:09 are going to be exploited quickly, which

18:11 means that your system has to be

18:13 designed differently. It has to be

18:16 designed to be fault tolerant to be able

18:17 to survive even if it's exploited. And

18:20 so that is

18:22 a different approach to security.

18:28 So let's talk about that a little bit

18:29 more. Cyber resilience after breach

18:32 because that's the perfect segway.

18:34 The statement assumes breaches are

18:36 inevitable.

18:38 and the question is in a KERI-based

18:40 architecture what remains trustworthy

18:42 after servers databases cloud providers

18:44 certificate authorities are compromised?

18:47 Well, in a KERI-based architecture,

18:50 what remains trustworthy is that you

18:52 have built a a fault-tolerant mechanism

18:56 that enables you to recover to detect

18:58 and recover from compromise.

19:02 And so what happens is that you

19:06 you may not be able to anticipate

19:08 all of the ways that an attacker can

19:12 attack you. But if you have mechanisms

19:14 that allow you to detect compromise

19:17 and then a way to recover from

19:20 compromise in a timely fashion, then the

19:23 attacker doesn't have time to exploit

19:26 that compromise. And like in a <i>Recursive</i>

19:29 <i>Privilege Escalation Attack</i>,

19:31 usually it's a sequence of exploits that

19:35 take time. Now the time doesn't have to

19:36 be very long. It might be

19:39 hours or days, now

19:43 prior to AI, well the

19:46 current the average time for a breach to

19:48 get detected currently and I

19:50 guess that's no less what you know

19:52 and having an AI as a protector might

19:56 reduce that time because it's better

19:57 able to detect breaches, right? That's

19:59 that's the idea. is 6 months and then

20:03 90 days after that to contain the

20:05 breach. So it's nine months of time that

20:07 an attacker has to to exploit the

20:11 vulnerability that they've discovered.

20:13 So KERI is designed so that

20:17 the detection time is on the order

20:20 of seconds. It's network propagation

20:22 time. So that breaches that are

20:26 exploitable

20:28 must exhibit detectability. So the whole

20:30 system's designed around

20:32 detectability, right?

20:35 Everything exhibits as <i>duplicity</i>.

20:38 It's a duplicity evidence system. So for

20:41 an attacker to benefit, they have to do

20:43 something that exhibits as duplicity,

20:46 which then enables

20:48 the controller of the identity to

20:50 recover from that in a timely

20:53 fashion. Which doesn't mean

20:55 that there aren't successful attacks.

20:57 It means that the blast radius of

21:00 the attack is minimized.

21:03 In many cases the ROI to the attack or

21:06 the return on investment is negative. I

21:09 mean it costs more

21:11 to execute the attack than they get from it

21:13 because the attack is quickly

21:17 contained and recovered from.

21:22 So these systems that we currently use,

21:24 servers, database, cloud providers,

21:26 certificate authorities, they're all

21:27 based on an antiquated, outdated notion

21:30 of security and key management. And

21:32 those are really harsh terms. And I know

21:33 a lot of people in the industry don't

21:34 like it when I say things like that, but

21:36 they are. It's 30 years old. And you can

21:38 walk back the choices

21:40 and they were good choices 30 years ago

21:42 or even 20 years ago or even 10 years

21:44 ago. Not so much 10 years ago, but 20

21:47 years ago for sure. But at least in

21:49 the last 10 years we've had better

21:51 technology for key management and KERI

21:54 is based on understanding that if

21:56 you have better technology for key

21:58 management then you do different

22:00 things. All of these systems that

22:04 that use DNS, TLS, OAuth, OIDC-based

22:10 systems all use shared secrets

22:13 and shared secrets are inherently weak

22:15 and inherently contribute to

22:19 <i>recursive privilege escalation attacks</i>.

22:21 And so it's really just figuring out

22:25 different ways to to exploit those

22:27 shared secrets. KERI doesn't use

22:29 shared secrets. It doesn't have any.

22:31 And so the protection

22:34 mechanisms are

22:36 fundamentally different, right?

22:38 If you don't share something, then somebody

22:40 can't capture it and collect it, right?

22:43 It requires a different type of attack.

22:45 And even if they're successful in that

22:46 attack, if you have a recovery

22:49 mechanism,

22:51 then you can recover from it.

22:54 And so you don't spend your time

22:55 trying to build a tank that's impervious

22:58 to any sort of bomb. You spend your time

23:02 building a squadron of tanks

23:06 so that some of them can be

23:08 destroyed, but the squadron survives and

23:10 repairs itself and is able to continue

23:12 to operate. And that's what <i>fault</i>

23:13 <i>tolerant</i> means. So I use that

23:16 analogy. You know, you can build a tank

23:18 with armor thick enough that withstand

23:19 any shell, but then it stops being a

23:22 tank which is mobile, right? By

23:24 definition, tank must be mobile.

23:26 So it goes from a tank to a bunker,

23:28 right?

23:31 You have to make some trades. And

23:34 and the right trade in

23:36 an AI world is a fault-tolerant system,

23:39 not a a system that you have to

23:42 throw away and start over with every few

23:45 days or months because

23:49 you can't tell whether or not you've

23:51 been attacked or breached because

23:52 you have no mechanism for

23:55 detecting compromise.

24:03 So actually this question,

24:05 I sort of jumped again on it, but how

24:07 does KERI suite shift security from

24:09 protecting infrastructure protecting

24:10 secrets to reveal verifable truths and

24:12 provenance. So the idea in cryptography,

24:15 in <i>asymmetric</i> cryptography,

24:18 is that you have private keys and public

24:21 keys; and private keys are truly

24:23 private in that they're never shared.

24:26 The problem is that people who

24:29 want to have a digital identity have

24:33 to manage those private keys. And so

24:35 that was always viewed as too difficult

24:36 a problem to manage. And so we needed to

24:39 have identity providers that manage

24:41 private keys on our behalf, right? And

24:43 then the key management was

24:45 hidden from the system. So you have

24:47 identity providers and relying

24:49 parties and then you use usernames

24:51 and passwords or now <i>Pass Keys</i>

24:54 There's stronger things than usernames

24:55 and passwords, but you're still relying

24:58 on an identity provider for the

25:01 ultimate security of the system. And that ends up

25:07 looking like shared secrets, <i>bearer</i>

25:10 <i>tokens</i>, that the identity provider

25:13 distributes around to people to

25:15 entities to be able to engage in things

25:18 over secure channels,

25:21 right? The secure channels

25:23 are protected with shared secrets. TLS,

25:26 you know, uses a Diffy-Helman key

25:28 exchange shared secret to

25:30 exchange an encryption key which is then

25:32 weakly authenticated by

25:36 encrypting something and then the other

25:37 side decrypts it and then sends it back

25:39 to you. But it's subject

25:41 to key-compromise <i>impersonation attacks</i>

25:43 and so anytime you start doing

25:46 things to avoid the hard problems of key

25:48 management, you end up weakening

25:50 security. KERI says "No, we're going

25:52 to build key management the right way."

25:54 "We're going to make it fault tolerant."

25:57 "And then we're going to

25:58 enable people to use it in a way

26:02 that requires too much effort

26:06 for the attack to be

26:10 successful." And KERI uses

26:13 <i>threshold</i> structures <i>multi-</i>

26:15 <i>signature</i>, <i>witness</i> pools, <i>watcher</i> pools

26:18 and delegated AIDs that are

26:21 hierarchical, so that you can build as

26:24 secure a system as you want; so that you

26:28 can tune the security to the value that

26:30 an attacker has to go for. So if it's

26:32 going after something really valuable,

26:34 then you layer on additional threshold

26:36 structures. And relative to the cost

26:41 of the resources to run a defensive

26:45 AI to protect your system, the

26:47 infrastructure for KERI is

26:49 trivally costly;

26:53 in comparison. So,

26:57 that's really the thing

26:59 that we're looking at.

27:05 Let's talk about privacy without

27:09 surveillance. Can strong

27:11 security, accountability, and resilience

27:13 be achieved without continuous

27:14 monitoring and surveillance? Right.

27:17 Well, it can.

27:21 Because what KERI does,

27:25 It says we're going to use

27:27 cryptography the way it was meant to be used.

27:33 Without explaining the KERI

27:35 protocol, which would take

27:36 too much time, it doesn't have the

27:41 weaknesses that our current shared-

27:42 secret based systems do, which are

27:45 vulnerable to exploit by AIs. AIs

27:50 can't brute force

27:53 a public key to get to a private key.

27:55 Now if I have a quantumcomputer that's

27:57 a different story but we now have

27:59 post-quantum public-private key

28:02 generation algorithms. And if your

28:05 system's cryptographically agile you

28:06 switch to them which KERI already is.

28:08 So that's a different problem.

28:12 so what they have to do is what's called

28:14 a side-channel attack. They have to find

28:15 a way to exploit through side channels.

28:19 Whereas a shared secret multiple parties

28:21 have a copy of that secret.

28:24 So the types of side-

28:27 channel attacks that work are much

28:29 greater. If I've got a

28:33 KERI private key that's truly private,

28:35 it's never shared. It never has to be

28:36 shared. And even if that private key is

28:39 compromised, I can recover from it

28:41 through KERI's <i>pre-rotation</i> mechanism,

28:45 then an attacker doesn't gain much by

28:47 compromising my private keys. They have

28:50 to compromise much more and that

28:52 much more can be designed to be low

28:55 friction for the user but high cost to

28:58 the attacker in such a way that you

29:01 invert the resource expenditure.

29:05 So it's too expensive to succeed in an

29:08 attack against the KERI infrastructure

29:10 than what you gain for it because of the

29:11 the inherent distributed nature

29:14 and decentralized nature of its design.

29:19 and I'll go back to this word

29:21 <i>balance privacy </i>and how does KERI

29:23 balance privacy and accountability?

29:26 Security

29:28 requires secure attribution. You need

29:31 to know who's doing what.

29:34 But you also

29:39 want to be able to control what

29:41 context

29:43 people know about who's doing what. And

29:46 KERI does that. KERI

29:48 gives you the ability to have

29:50 identifiers that you use in specific

29:52 contexts that are not correlatable to

29:54 identifiers you use in other contexts.

29:56 But in each context, you have

30:00 perfectly secure attribution to all the

30:02 parties in the context. And what that

30:04 means is that you get rid of the

30:07 main source of fraud which is

30:10 impersonation attacks which deep

30:12 fakes all of those things because every

30:15 participant must be accountable in that

30:18 context. They can't

30:21 pretend to be somebody else

30:23 because you can challenge them and they

30:25 have to prove that link. So if it's an AI,

30:26 that's an agent working on behalf of

30:29 somebody, you can challenge

30:33 all the way back to that person. If

30:34 you're using KERI and that

30:37 person is delegating authority to an

30:39 agentic AI, then you can

30:42 always establish the chain of authority,

30:44 right? So accountability comes

30:47 from chains of accountability or

30:50 chains of authority or chains of

30:51 provenence or chains of custody.

30:55 and KERI inherently is designed

30:58 to support those sorts of structures.

31:01 Whereas most security systems are flat.

31:03 They don't have this hierarchy that

31:06 enables you to establish these

31:08 delegations that are strongly

31:11 cryptographically-verifiably chained

31:13 together.

31:18 privacy without surveillance. What is

31:19 the minimum amount of data disclosure

31:21 needed to achieve accountability without

31:23 creating surveillance society?

31:26 That's an interesting question.

31:29 Basically,

31:31 in each context, each transaction, each

31:33 application, the minimum is different

31:36 because for high-stakes transactions,

31:40 where there's high value,

31:43 usually the amount of trust required

31:46 amongst the parties is higher. That

31:48 means they need to be able to better

31:50 predict

31:52 the outcome and the behavior of the

31:55 participants to that interaction.

31:58 For low-stakes interactions, the

32:00 amount is much less. So you need a

32:03 system that gives you enough for

32:07 the highest transactions

32:09 but still allows you to tune it for

32:12 the lowest-stakes transactions and

32:14 KERI does that. But how do you

32:17 not create a

32:19 surveillance society? Well,

32:21 everybody in that transaction has to

32:24 have balanced obligations,

32:28 right? How do you need it to achieve

32:32 accountability without creating

32:33 surveillance? Well, if the surveillors

32:36 are accountable,

32:38 then the people being surveilled will

32:40 have recourse against the surveillance.

32:43 And this a change in

32:46 philosophy. It's been for the last 15

32:50 years that I've been working in this

32:51 space, we were hoping

32:53 that there were technological means

32:55 where you could hide. Well, basically

32:57 you could engage in transactions and

32:59 hide from surveillance. And that's not

33:01 true. With AI, there's no hiding.

33:05 If the data is on the internet, it's going

33:07 to be correlated. Even the smallest

33:08 signal is correlatable given

33:11 enough coverage; and AIs have

33:14 enough coverage, right? People are

33:15 building AI data centers

33:20 that are going to consume a

33:21 significant fraction of the world's

33:23 global electrical production and what do

33:26 they do? They correlate, they're

33:27 correlation machines and they consume

33:29 all the possible data that you can give

33:31 them and correlate everything so

33:32 that every point of information

33:35 becomes a correlatable signal that

33:38 results in something that is

33:41 actionable. So you're not going to

33:43 stop the correlation. What you can stop

33:45 is the <i>exploitation</i> of the correlation

33:47 and that means putting accountability on

33:49 the exploiters.

33:52 That requires a

33:56 slightly different ,well, a profoundly

33:59 different legal and regulatory

34:04 approach. But from an identity point of

34:06 view, it requires understanding that

34:09 that hiding isn't how you

34:12 do it. You can partition contexts so

34:15 that you can keep the

34:19 interaction space from leaking out too

34:21 fast, but it will leak. No matter what

34:24 you do, it will leak. But what you want

34:26 to be able to do is make your ability to

34:29 enforce the exploitation or

34:32 misuse of that data stronger. And that

34:34 and so contextually,

34:37 Contextually-specific identifiers

34:40 can be used to remove plausible

34:43 deniability by the other parties to

34:46 those transactions. So there's

34:49 some specific things we can do.

34:53 We're left with a stark choice.

34:59 If frontier AI reaches superhuman

35:01 offensive cyber capability, do our

35:03 choices become increasingly stark? They

35:05 they do. In fact, a lot of the

35:07 discussions I've been having over the

35:09 last few years are often in the

35:10 decentralized identity space, and

35:12 they're usually discussions about, well,

35:15 we want to weaken security, so

35:17 we can get privacy. We're willing to

35:19 make trade-offs along those lines. And I

35:20 I've always said you can't weaken

35:22 security. If you weaken security, if you

35:24 give up security for privacy, then you

35:26 get neither. And now that's become

35:28 obvious. It's sort of like: now, if you

35:32 want security at all,

35:36 it's really hard. And

35:40 if you don't have security, then you

35:42 have nothing. Because if you can be

35:43 impersonated

35:45 at will by an AI,

35:49 then you have no identity. And

35:51 therefore, you have nothing that's

35:52 private, right? Because I can't

35:55 assume that anything that I do can be

35:57 kept private if an AI can impersonate me

36:01 and prove to the rest of the world that

36:03 it was me that did it.

36:06 Basically, what does that mean? See,

36:08 people think about privacy as well, I

36:09 can do things that nobody else can do

36:11 and nobody knows about. But if

36:15 someone can attribute to me, behavior

36:19 that I didn't do and I can't disprove it

36:22 and I then suffer the consequences of

36:24 it, what does that mean in terms of

36:27 me having any sort of private life? It

36:29 means I don't, it means my life is governed

36:32 and determined by outside forces. My

36:35 <i>locus of control</i> is zero and

36:38 so privacy is meaningless when

36:40 when your locus of control is zero.

36:42 What does it mean? It doesn't mean

36:44 anything. You're you're essentially a

36:46 serf or a slave or a

36:49 minion of the forces that control

36:52 your identity. So it starts

36:55 with control. You have to have

36:57 control before you can have privacy.

37:01 And so the stark choice is

37:05 you need to have security before you can

37:08 have privacy and you can either have

37:10 security that has zero privacy which is

37:13 which is an AI-based identity system

37:16 because it requires total continuous

37:19 monitoring and surveillance and be able

37:20 to do a better job at correlating your

37:22 behavior to create your digital persona

37:24 than the cyber attackers are doing to

37:27 impersonate your persona. Or you use

37:29 KERI which is based on a

37:32 cryptographically-verifiable identity

37:34 that's fault tolerant, uses key

37:36 management provenance and

37:37 accountability. So it doesn't solve the

37:40 privacy problem the same way that you

37:41 might think but it does solve it in the

37:43 only way possible in today's

37:45 environment.

37:49 Why is there no stable middle ground? I

37:51 think I just answered that. If AI-

37:54 cyber-based attack mechanisms can defeat

37:58 conventional security, based on shared

38:02 secrets, not KERI, then there is no

38:06 privacy. It's total surveillance in

38:09 order for you to have any possibility of

38:11 having any sort of value in your life.

38:15 Otherwise, you can't

38:18 do anything on the

38:20 internet. You have to go off-grid.

38:22 Totally off-grid. Like off-grid in a way

38:24 that would be for most people a

38:28 horrible life.

38:34 This is an interesting question. As

38:37 AI capabilities increase, why does

38:39 continuous tracking or surveillance

38:40 based trust become less sustainable than

38:42 cryptographically-verifiable trust? The

38:44 reason it becomes less sustainable is

38:47 that it's a never-ending arms race.

38:51 The information that's electronic, once it leaks

38:57 out, it never goes away.

39:00 And it enables correlation to be all

39:03 that much better. The correlation

39:04 algorithms, the tracking algorithms,

39:07 target tracking. You can think

39:11 of as there's a feature space and if I'm

39:15 tracking something, it's moving through

39:16 that feature space. Now, in the physical

39:18 world, that feature space might be,

39:20 latitude, longitude,

39:23 altitude and time, right? And

39:26 then you got velocity, acceleration, all of those things, right?

39:30 But in identity world,

39:34 the feature space has to do with

39:36 things like "when you logged in, to where

39:38 did you log in, what did you do, what

39:39 did you say, what time was it,

39:42 what browser did you use, what device

39:44 did you use, what protocol did you use?'

39:47 All of those are features that can

39:50 be used to create a digital fingerprint

39:53 that then can be tracked as you

39:56 move through that space. And so it forms

39:59 a trajectory of your behavior. And the

40:03 more information you have, the more

40:04 high fidelity that trajectory is. People

40:07 call it a digital twin. So they're

40:09 creating a digital twin. And they want

40:10 that digital twin to be as close to you

40:12 as possible so that somebody can't

40:15 create a digital twin that is not yours.

40:18 And your AI that's working on

40:20 your behalf can tell the difference.

40:22 Right? Well, that means that

40:24 increasingly, as AIs gain access to

40:28 more and more information, as more and

40:30 more of our society and more and more of

40:32 what we do becomes AI enabled, then the

40:36 information available to both track you

40:38 and impersonate you increases. So,

40:42 what happens is the pervasiveness will

40:44 always go to maximal, right?

40:47 There's no other approach and

40:51 maximal means high resource, I

40:55 mean we're already talking about that

40:57 most of the world's electricity being

40:59 consumed by AIs. Well it's only going

41:01 to get more as time goes on

41:04 it doesn't get less it gets

41:06 more, whereas cryptographically

41:09 verifiable trust is based on a

41:10 completely different set of constraints

41:13 that have to do with what's called

41:15 computational infeasibility

41:18 and exposure. And if you don't

41:20 expose something, so that it can't be

41:22 collected, if it's a true private

41:25 piece of information and you can

41:28 prove something publicly without

41:32 disclosing the private thing, that's

41:33 what a digital signature does. There's

41:35 various types of proofs and you can

41:37 prove that indefinitely or

41:41 perpetually. So you have perpetually

41:43 verifiable proofs. Then you have the

41:45 foundation for a security system that

41:50 maintains the security without getting

41:52 more expensive over time. In fact, it

41:54 gets less expensive over time because

41:56 most of the cost is really reducing

41:58 user interface friction. We're in

42:01 the early days of reducing user

42:02 interface friction. So that

42:04 becomes a perfectly scalable system

42:06 relative to the alternative

42:12 Keeping humans digitally free as

42:14 AI becomes the dominant interface to the

42:16 digital world. How must KERI be applied

42:18 to AI itself so that people remain

42:21 digitally free rather than becoming

42:22 exploitable, surveilled, tracked,

42:24 manipulated or controlled? Well, we want

42:28 AI to work on our behalf. We want the

42:30 best of both worlds. We want AI that

42:32 does what we tell it to do, when we tell

42:35 it to do it, to the extent we tell it to

42:37 do it. And for that, we need to be able

42:39 to have strong delegation

42:42 and have enforcement mechanisms

42:46 where we can publish to other AIs that

42:49 says "Our AI is only supposed to do this."

42:52 These are the rules. You can verify what

42:54 it's supposed to do. When it doesn't

42:56 then you cannot trust my AI.

43:03 And so there are people

43:05 talking about reputation

43:08 systems for AIs but those reputation

43:10 systems have to be managed in a way that

43:14 humans control and we can do that with

43:16 KERI. If you have

43:19 identity systems that allow secure

43:21 attribution that are not based on

43:23 correlation-tracking mechanism but are

43:25 based on cryptographic mechanisms. Then

43:27 you can build delegation mechanisms and

43:29 authorization mechanisms that are

43:31 fundamentally different in structure.

43:33 They break this flat weight

43:36 space constraint that AI has right now

43:38 that makes it impossible to secure AI

43:41 because everything's in the same

43:43 weight space to where you can actually

43:45 partition or segment the weight space

43:47 into things that are delegable and

43:49 things that aren't.

43:52 Should AI be trusted to protect human

43:54 freedom or should AI itself be

43:56 constrained by cryptographically

43:57 variable trust architecture that keeps

43:59 ultimate authority with people? Well,

44:01 there are a lot of people who are

44:02 talking about the fact that AI can't be

44:04 trusted and doom and gloom for

44:07 society once an AI becomes smart enough.

44:10 I think, I spent 20

44:13 years doing research in AI systems. In

44:15 fact, I did that for the early part of

44:18 my career before I started working on

44:20 digital identity. And yeah, we can

44:23 build we can build transparent AIs

44:26 that only do things that we allow

44:29 them to do if we architect them

44:31 differently. That doesn't mean that we

44:33 have to throw away generative AI.

44:37 We just have to partition

44:40 the space in which it

44:43 operates so that it's one thing to have

44:46 a generative AI that understands

44:49 natural language. It's another thing to

44:51 have a generative AI that you allow to

44:56 to do things on your behalf; that's an

44:58 agent. So we can have a gentic AI that

45:00 is controlled but uses you know

45:03 interfaces and that means that the

45:05 the interface layer has to have

45:10 safety jackets and when I used to do

45:12 work with autonomous vehicle systems

45:14 most of the code we wrote were safety

45:16 jackets to keep the autonomous vehicle

45:18 alive and well and safe and to

45:22 keep it from doing bad things. But we

45:25 sort of forgotten about that.

45:28 People are worried about

45:30 that. I mean a lot of people are trying

45:32 to build those but they're building it

45:34 with systems that

45:37 they're using the same AI for, to secure

45:40 the safety jackets and you

45:44 can't do that. The safety jackets has to

45:46 be foundationally different in nature

45:48 from a computational point of view.

45:50 And if you do that, then you have a chance.

45:54 What would a world look like where every

45:56 AI agent operates under

45:57 cryptographically-verified authority by

45:59 delegation and thus accountability?

46:01 Well, it'd be the best of both worlds.

46:02 We would be able to have AI

46:05 help us be a force multiplier for us

46:08 without worried about the AI hurting us.

46:11 There's always going to be

46:16 edge cases where people will make

46:19 mistakes and AIs will be able to exploit

46:22 things, but it won't be this

46:24 Armageddon kind of situation that we're

46:27 facing right now. The race against

46:29 time. If frontier AI is advancing on

46:32 time scale, months rather than years,

46:34 how quickly can society realistically

46:35 deploy either of these features at

46:37 global scale? Well, the stark

46:40 reality is the only thing that you're

46:42 going to be able to deploy at global

46:43 scale today is AI because AI is already

46:47 deployed at a global scale, right?

46:50 But that doesn't mean that you

46:52 can't switch to KERI as it becomes

46:55 available to you, right? You can always

46:57 make the choice to say "you know what?,

46:59 I've been using this digital persona

47:01 AI, but I want to switch to using

47:05 cryptographically-verifiable human ...,

47:07 individual-controlled identity

47:10 system." And so there, as I mentioned

47:13 early in the talk, there are adoption

47:15 vectors. People are spending resources,

47:16 but nowhere near the amount of resources

47:19 going into AI systems, into AI

47:22 identity system. If we had a fraction of

47:24 that spend going into KERI, KERI

47:27 would already be available. But

47:29 we're looking at rolling out KERI for

47:32 the State Endorsed Digital Identity (SEDI)

47:34 initiative in the next

47:37 12 months. So, we're really close and

47:39 like I said, they're already using

47:40 KERI in the early adoption in

47:44 the telecom sector and the healthcare sector.

47:53 So the seed has been planted.

47:55 We've got shoots growing out of

47:57 ground but those shoots can grow

47:58 exponentially fast. All they need is

48:00 sunlight, water and soil and

48:05 resources. So we just need resources and

48:08 and the adoption can go much faster.

48:11 Once adopted, then it becomes a bulwark

48:13 against future encroachment. So, we

48:16 get off the

48:19 arms race. We stop being in a

48:21 resource arms race. We do a one-time

48:23 spend to convert to KERI and then we

48:25 don't have to keep spending

48:27 and spending to protect ourselves.

48:32 Which approach can be deployed more

48:34 quickly, more safely, more humanely

48:35 at planetary scale? Well,

48:37 that's a trick question.

48:41 Certainly, more safely and more

48:44 humanely, KERI. More quickly? Not today

48:48 but five years from now, possibly,

48:51 because you don't have to every five years

48:57 double the number of

49:00 servers that you have running in AI

49:02 data centers you don't have to fill

49:05 space with AI data centers and able

49:08 to keep up with the arms race. So yeah,

49:11 so on a 5-year time frame, if quick

49:15 is 5 years, then KERI definitely

49:17 is the only viable choice.

49:21 What are the biggest technical economic

49:24 political and adoption barriers to

49:25 deploying SEDI/KERISuite fast enough to become

49:28 a viable alternative before surveillance-

49:30 based systems become entrenched? Well,

49:33 one is just people don't know about it.

49:36 so they don't know to that it's

49:37 that actually is a viable choice. The

49:40 other is that society is filled

49:43 with lots of people who are unaware of

49:44 this threat and so they still think that

49:47 old systems are the way to go and so

49:51 they're sort of having the

49:57 old fashioned arguments.

49:59 It's like they're moving

50:00 moving the deck shows on the

50:02 Titanic, right? The Titanic's going

50:04 down. It's going to go down in an hour,

50:07 right?

50:09 As soon as the whole breaches

50:11 and it cracks in half, it's gone, right?

50:14 But you have this sense that "Oh

50:16 well, it's still floating, so we've got

50:19 time, right? We've got time,

50:21 and there's no rush." And the fact

50:24 of the matter is you don't have

50:26 time, which means that you should stop

50:29 worrying about anything other than these

50:31 two alternatives. And if you stop

50:33 worrying about all the alternatives

50:35 but these two, then it becomes pretty

50:38 clear where for most people

50:40 that care about this stuff

50:44 where their effort should go that

50:46 they should be helping ..., because nothing

50:48 else is good enough

50:50 besides KERI. There are lots of "KERI light"

50:53 or partial KERI or they

50:56 do some of KERI but not all of KERI

50:58 stuff out there. And the problem is

51:00 that those systems aren't good enough

51:03 because they leave out important things

51:04 you need to protect against the AI

51:06 threat. So they're half measures,

51:08 right? And half measures aren't good

51:10 enough, right? No more half measures.

51:12 We use that motto

51:15 If you care about security, you can't do

51:17 half measures. `You're either

51:19 sufficiently secure or you're wiped

51:22 out.` So that's the alternative.

51:26 And I have this picture that I got

51:28 from Chris Bramwell who's working on

51:31 this SEDI for the State of Utah.

51:34 SEDI: the last best hope against

51:38 AI. So it shows SEDI as a warrior,

51:42 The knight to fight the

51:44 AI scourge of identity. Not that AI

51:51 is inherently evil. It's just that the

51:55 the only solution that an AI-based

51:57 identity gives us is a centralized,

52:01 identity that requires maximal

52:04 surveillance. It's basically you need

52:06 to be continuously surveilled, so that it

52:08 can build a high-fidelity persona of

52:12 you that is better than the

52:15 attacker's AI, who is also continuously

52:18 surveilling you, trying to build a

52:21 sufficiently-high fidelity that

52:23 it can steal your

52:26 identity and exploit you. And

52:30 that's a stark choice. Neither of those

52:32 are good, right? Neither of those

52:34 are where we want to end up. We want to

52:36 get off that train. KERI is

52:38 is a path to get off that train.

52:41 I hope this has been helpful. I hope

52:43 that if you're worried,

52:46 if you're <i>only</i> worried, then

52:49 you're not taking this seriously

52:50 enough. You should be

52:56 worried like you've never been

53:01 before about the future of digital

53:03 identity. Given how fast the

53:07 frontier AI models are growing in their

53:11 ability to exploit current digital

53:14 identity systems which all

53:15 security systems are foundationally

53:17 based on digital identity systems.

53:19 You use digital identity security

53:22 overlay for everything else that you're

53:24 doing. If those are breakable,

53:26 then we're looking at an impending

53:31 catastrophe. What's

53:37 going to end up happening is people are

53:38 just going to adopt the easy path

53:41 which is adopt AI-based

53:47 digital identity.

53:51 That would be a bad choice for

53:53 us. Maybe in the short run it's the

53:55 only choice available to us because

53:56 KERI isn't universally available.

53:59 It's still a chute in the ground. Not

54:06 not a whole field of

54:09 plants. But it could be a whole

54:11 field of plants in the next

54:14 couple of years. Not in the next

54:16 couple of months, not unless

54:17 a bunch of resources get thrown at it,

54:19 which I don't think is going to happen.

54:21 Video: Sam and Caleb Smith Subtitles: Henk van Cann and Kor Dwarshuis